CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96501  CVE-2016-9681  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a category or directory name.  Assigned (20161130)  None (candidate not yet proposed)    View
96502  CVE-2016-9682  Candidate  The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system. The application doesn"t properly escape the information passed in the "tsrDeleteRestartedFile" or "currentTSREmailTo" variables before making a call to system(), allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.  Assigned (20161130)  None (candidate not yet proposed)    View
96503  CVE-2016-9683  Candidate  The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the "extensionsettings" CGI (/cgi-bin/extensionsettings) component responsible for handling some of the server"s internal configurations. The CGI application doesn"t properly escape the information it"s passed when processing a particular multi-part form request involving scripts. The filename of the "scriptname" variable is read in unsanitized before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account. This is SonicWall Issue ID 181195.  Assigned (20161130)  None (candidate not yet proposed)    View
96504  CVE-2016-9684  Candidate  The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the "viewcert" CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application doesn"t properly escape the information it"s passed in the "CERT" variable before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.  Assigned (20161130)  None (candidate not yet proposed)    View
96505  CVE-2016-9685  Candidate  Multiple memory leaks in error paths in fs/xfs/xfs_attr_list.c in the Linux kernel before 4.5.1 allow local users to cause a denial of service (memory consumption) via crafted XFS filesystem operations.  Assigned (20161130)  None (candidate not yet proposed)    View

Page 19301 of 20943, showing 5 records out of 104715 total, starting on record 96501, ending on 96505

Actions